LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-06-2005, 04:01 PM   #1
ryedunn
Member
 
Registered: Jul 2003
Location: Chicago
Distribution: Fedora, ubuntu
Posts: 459

Rep: Reputation: 30
Is my box port scanning?


I finally got acid working correctly and I see all these fun attacks coming in but there is one thing that I dont quite understand.

Under my Destination IP address I saw 2 IPs.. hmm I only have one IP so I went in to look at it and sure enough there was another IP address in there. I clicked on the number of attacks and it looks like Im sending out attacks to him....
Quote:
ID #1-(1-4)
< Signature > [snort] ATTACK-RESPONSES 403 Forbidden
< Timestamp > 2005-01-06 14:39:02
< Source Address > My IP:80
< Dest. Address > His IP:1591
< Layer 4 Proto > TCP
As you can see the source address is me sending out....My worst fear is that my box has already been comprimised and Im scanning other addresses.

Thank you
Ryan
 
Old 01-06-2005, 05:05 PM   #2
ryedunn
Member
 
Registered: Jul 2003
Location: Chicago
Distribution: Fedora, ubuntu
Posts: 459

Original Poster
Rep: Reputation: 30
I think its just my reply to some attacks.... ie ATTACK-RESPONSES 403 Forbidden ..


I hope...
 
Old 01-07-2005, 04:45 AM   #3
iceman47
Senior Member
 
Registered: Oct 2002
Location: Belgium
Distribution: Debian, Free/OpenBSD
Posts: 1,123

Rep: Reputation: 47
I'm just guessing here, but are you running a webserver?
src ip is you, src port is 80, dst ip is him and sig is a 403, seems like he's trying to get a page
from you but as it's not there you're sending a 403 back.
Correct me if I'm wrong here.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Port scanning? muppski Linux - Security 6 07-01-2005 05:44 PM
Can I protect my RedHat 7.2 box from port scanning? yuzuohong Linux - Networking 2 06-05-2003 05:54 PM
Smart Port Scanning? Half_Elf Linux - Security 1 01-25-2002 11:28 PM
port scanning johncla Linux - Networking 1 05-02-2001 03:09 AM
Port Scanning tfrye Linux - Security 2 03-24-2001 09:43 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration